EGI CSIRT:Central emergency suspension

From EGIWiki
Jump to: navigation, search
EGI-CSIRT web site EGI-CSIRT Public wiki EGI-CSIRT Contacts EGI-CSIRT Activities EGI-CSIRT Private wiki


Contents


Central emergency suspension procedure

The document describing the central emergency suspension procedure is available at EGI CSIRT Operational Procedure for Compromised Certificates.

Argus Infrastructure Deployment

Argus Monitoring

NGI Argus Monitoring

The eu.egi.Argus-DNs metric checks if an Argus server is properly configured and still pulling suspension information from the Central Argus Instance.

Every day the Central Argus Instance suspends a new DN: the probe verifies if this DN is present on the NGI argus.

The return values of that probe can indicate the following problems:

Return value Problem Potential solution
ARGUS WARN - connection error The probe was not able to connect to the Argus server Please make sure that the argus pap port (8150) is accessible remotely from argo-mon.egi.eu, argo-mon2.egi.eu and argo-mon-test.cro-ngi.hr
ARGUS WARN - Authorization error The probe was able to connect but was denied access POLICY_READ_REMOTE|CONFIGURATION_READ" permissions are given to "/DC=EU/DC=EGI/C=HR/O=Robots/O=SRCE/CN=Robot:argo-egi@cro-ngi.hr" and "/DC=EU/DC=EGI/C=GR/O=Robots/O=Greek Research and Technology Network/CN=Robot:argo-egi@grnet.gr"
ARGUS CRIT - Expected DN not found! The probe didn't find a recent DN in the Argus configuration Please check your argus logs to see what is blocking the synchronization
ARGUS WARN - Found outdated DN The probe only found an outdate DN and not the current one Please check your argus logs to see what is delaying the synchronization. The synchronization delay might be too long
ARGUS OK - Found expected DN Everything is good!

For more details on the Argus configuration see bellow.

Site Monitoring

Site Arguses (or equivalent solutions) should not be exposed to the internet and thus cannot be directly monitored However the EGI CSIRT is considering submitting jobs from suspended DNs, but such monitoring of the sites' emergency suspension systems is not yet in place.

Argus Support

Support is provided through ARGUS Support unit in GGUS

Documentation

Documentation on possible problems and solutions with certain deployment scenarios are in Nikhef wiki, Argus Global Banning Setup Overview

Personal tools
Namespaces
Variants
Actions
Navigation
Toolbox
Print/export